Results
| Paper | Avail. | Funct. | Repro. | Available At |
|---|---|---|---|---|
| A Cuckoo in the Nest: MultiβStage, MultiβIdentifier Hijacking in BACnet/SC |
|
π¦ Artifact |
||
| A Distortion-minimization Watermarking Framework for Large Language Models: Larger Capacity, Stronger Robustness and Higher Quality |
|
π¦ Artifact |
||
| A Formal Security Analysis of CAN XL |
|
|
|
π¦ Artifact π Appendix |
| A Large-Scale Study of Personalized Phishing using Large Language Models |
|
π¦ Artifact |
||
| A Midsummer Memeβs Dream: Investigating Market Manipulations in the Meme Coin Ecosystem |
|
π¦ Artifact |
||
| ARM MTE Performance in Practice |
|
π¦ Artifact |
||
| ARTO: Efficient Execution Integrity Attestation for Real-Time Operation of Cyber-Physical Systems |
|
|
π¦ Artifact π Appendix |
|
| ASRogue: Manipulating ASRank-Inferred AS Relationships |
|
π¦ Artifact |
||
| Abuse Risks are Often Inherent to Product Features: Exploring AI Vendorsβ Bug Bounty and Responsible Disclosure Policies |
|
π¦ Artifact |
||
| Adversarial Patch EXterminator: Zero-Shot and Patch-Agnostic Defense Framework Against Adversarial Patch Attacks |
|
|
|
π¦ Artifact π Appendix |
| Ajax: Fast Threshold Fully Homomorphic Encryption without Noise Flooding |
|
π¦ Artifact |
||
| Alias Equals Zone? Large-Scale and Stealthy Takeover of Domain Hosting Service via CNAME-Following Cross-Domain Verification |
|
π¦ Artifact |
||
| Amortizing Randomness Cost: Efficient Masked Implementation of SDitH Signatures with Common Shares |
|
π¦ Artifact |
||
| Analyzing Cryptography in Context: A Cryptography-Native Approach to Threat Modeling |
|
|||
| Analyzing the WebRTC Ecosystem and Breaking Authentication in DTLS-SRTP |
|
π¦ Artifact |
||
| Anamorphic Messaging: Analyzing the Double Ratchet, Triple Ratchet, PQ3, and MLS |
|
|||
| Anchors that Donβt Lift: Understanding Supply Chain Driven Kernel Lock-In and Governance-Mediated Mitigation Strategies in SOHO Devices |
|
π¦ Artifact |
||
| Anonymous Tokens with Designated-Reader Metadata Bit |
|
|
|
π¦ Artifact π Appendix |
| Arguzz: Testing zkVMs for Soundness and Completeness Bugs |
|
π¦ Artifact |
||
| Artifacts for BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems |
|
π¦ Artifact |
||
| Artifacts for X-rated Compliance Theater: An Empirical Evaluation of European Age Verification Systems in Adult Websites |
|
π¦ Artifact |
||
| Assessing LLM Response Quality in the Context of Technology-Facilitated Abuse |
|
π¦ Artifact |
||
| Attacks on Approximate Caches in Text-to-Image Diffusion Models |
|
π¦ Artifact |
||
| AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations |
|
π¦ Artifact |
||
| AutoFail: Breaking Web Boundaries using Androidβs Autofill Framework |
|
|
π¦ Artifact π Appendix |
|
| Autonomy Comes with Costs: Detecting Denial-of-Service Vulnerabilities Caused by Resource Abusing in LLM-based Agents |
|
π¦ Artifact |
||
| B-Privacy: Defining and Enforcing Privacy in Weighted Voting |
|
π¦ Artifact |
||
| BADControl: Backdoor Attacks Against Control Systems |
|
π¦ Artifact |
||
| BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems |
|
|
|
π¦ Artifact π Appendix |
| BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User Interface |
|
|
π¦ Artifact π Appendix |
|
| BULBASAUR: Branch-Guided Online Mutator Generation for Greybox Fuzzing |
|
π¦ Artifact |
||
| BadGraph: Structural Knowledge Isolation Attacks against Graph Retrieval-Augmented Generation |
|
π¦ Artifact |
||
| BatchBoot: Fast Batched Bootstrapping for TFHE scheme and Practical Applications |
|
π¦ Artifact |
||
| Behind Bars: A Side-Channel Attack on NVIDIA MIG Cache Partitioning Using Memory Barriers |
|
π¦ Artifact |
||
| BenchChecker: Assessing the Credibility of Bug-Fixing Benchmarks for LLMs |
|
|
π¦ Artifact π Appendix |
|
| Beyond the Stars: Multimodal Detection of Scams on GitHub |
|
π¦ Artifact |
||
| BlockMeNot: Automatic Selection of Domain and URL Blocking Granularity to Minimize Collateral Damage and Evasion |
|
π¦ Artifact |
||
| Boosting Efficiency and Security in Arithmetization-Oriented Hashing for Zero-Knowledge Proof Systems |
|
π¦ Artifact |
||
| Breaking the Boundaries: Analyzing QUIC Frame-Packet Interactions With QUIC-Attacker |
|
|
π¦ Artifact π Appendix |
|
| Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost |
|
π¦ Artifact |
||
| Bridging Bitcoin to Second Layers via BitVM2 |
|
|
|
π¦ Artifact π Appendix |
| Bridging Usability and Performance: A Tensor Compiler for Autovectorizing Homomorphic Encryption |
|
|
|
π¦ Artifact π Appendix |
| BugAuditor: Detecting Bugs via Inconsistent Defensive Code Auditing |
|
|
|
π¦ Artifact π Appendix |
| Butterfly: Scalable Multi-Party Circuit-PSI via Triplet Zero-Sharing |
|
π¦ Artifact |
||
| Bypassing Prompt Guards in Production with Controlled-Release Prompting |
|
π¦ Artifact |
||
| COGNITION: From Evaluation to Defense against Multimodal LLM CAPTCHA Solvers |
|
π¦ Artifact |
||
| CTA: Clip-then-Aggregate, a Differentially Private Learning Algorithm for Graph Data |
|
π¦ Artifact |
||
| CULPA: Universal Detection of Memory-Safety Bugs in Unsafe Rust Through the Lens of Safety Requirements |
|
|
|
π¦ Artifact π Appendix |
| Can we estimate privacy vulnerability of individual records? Towards Mitigating Attribute Inference Attacks on ML Models |
|
|
|
π¦ Artifact π Appendix |
| Certification of Machine Learning Models via Directional Sharpness |
|
π¦ Artifact |
||
| Certified in Theory, Broken in Practice: Assumption Gaps in Cryptographic Model Certification |
|
|
π¦ Artifact π Appendix |
|
| Chameleon Channels: Measuring YouTube Accounts Repurposed for Deception and Profit |
|
|
|
π¦ Artifact π Appendix |
| Characterizing Security and Privacy Teaching Standards for Schools in the United States |
|
|
π¦ Artifact π Appendix |
|
| Charting the Cache Side-Channel Frontier: A Systematic Study of Eviction Set Construction on Apple Silicon |
|
|
|
π¦ Artifact π Appendix |
| Cloud-Native Carjacking: Fleet-wide Compromise via Telematics Authorization Failures |
|
π¦ Artifact |
||
| CoKeMon: Configurable Kernel Monitoring by Decoupling Isolation |
|
π¦ Artifact |
||
| CombiSan: Unifying Software Sanitizers for Comprehensive Fuzzing |
|
|
|
π¦ Artifact π Appendix |
| CompLeak: Deep Learning Model Compression Exacerbates Privacy Leakage |
|
|
|
π¦ Artifacts: 1, 2 π Appendix |
| Concretely efficient blind signatures based on VOLE-in-the-head proofs and the MAYO trapdoor |
|
|
|
π¦ Artifact π Appendix |
| Concurrency Fuzzing of the Linux Kernel with eBPF |
|
|
π¦ Artifact |
|
| Confundo: Learning to Generate Robust Poison for Practical RAG Systems |
|
π¦ Artifact |
||
| Connect the Dots: Knowledge GraphβGuided Crawler Attack on Retrieval-Augmented Generation Systems |
|
π¦ Artifact |
||
| Context Contamination in LLM Analysis of Network Security Logs: Poison with Passive Prompt Injection and Mitigation Evaluation |
|
π¦ Artifact |
||
| Cordyceps: Covert Control Attacks on LLMs via Data Poisoning |
|
π¦ Artifact |
||
| Cracking Federated Privacy: Initialization-Resilient Gradient Inversion with Fine-Grained Reconstruction |
|
π¦ Artifact |
||
| Cracks in the Walled Garden: Dissecting the Gray-Market of Unauthorized iOS App Distribution via Ad Hoc Sideloading |
|
π¦ Artifacts: 1, 2 |
||
| Credible Threat Detection? Measuring Contribution Dynamics and Quality Control in a Crowdsourced Threat Detection Ecosystem |
|
π¦ Artifact |
||
| Cross-National Information Attacks: A Two-Decade Analysis of Troll Behavior in Korea |
|
|
π¦ Artifact π Appendix |
|
| Cryptanalysis of LDPC-Based Pseudorandom Error-Correcting Codes |
|
|
|
π¦ Artifact π Appendix |
| Crypto Wars in Secure Messaging: Covert Channels in Signal Despite Leaked Keys |
|
π¦ Artifact |
||
| CuSafe: Capturing Memory Corruption on NVIDIA GPUs |
|
π¦ Artifact |
||
| Cutting the Fuse: Actionable APT Attack Blocking in Provenance-based IDS |
|
π¦ Artifact |
||
| Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework |
|
π¦ Artifact |
||
| DDR-SSE: Duplicated Retrieval of Documents for System-wide Secure Searchable Symmetric Encryption |
|
|
|
π¦ Artifact π Appendix |
| DMGuard: Safeguarding Kernels from Physical-Page Use-After-Free Vulnerabilities |
|
|
|
π¦ Artifact π Appendix |
| DNS Cache Poisoning Like its 2006 |
|
|
|
π¦ Artifact π Appendix |
| DP-SAPF: Saliency-Aware Parameter Fine-tuning of Public Models for Differentially Private Image Synthesis |
|
π¦ Artifact |
||
| DRVFuzz: Data-Sensitive RISC-V CPU Fuzzing |
|
|
|
π¦ Artifact π Appendix |
| DUPIN: Attack Learning Is Still Needed! Demonstrating Few-Shot after Unsupervised Pretraining Is A Nimble Forensics Learner |
|
π¦ Artifact |
||
| DaLens: Charting DNS Self-Amplification Threats at Large |
|
π¦ Artifact |
||
| Death by a Thousand Drips: Uncovering Critical Resource Leaks in the Windows Ecosystem |
|
π¦ Artifact |
||
| Defending Jailbreak Attacks on Large Language Models via Manifold Trajectory Kinetics |
|
π¦ Artifact |
||
| Designing Wallet-Based User Intervention for Approval Phishing Mitigation |
|
π¦ Artifact |
||
| Differential Trust: Dynamic Multi-Authority Anonymous Credentials with Epoch-Weighted Updates |
|
π¦ Artifact |
||
| Digital Risks and Coping Practices among Roblox Game Creators |
|
π¦ Artifact |
||
| Discovering, characterizing and exploiting controllable-copy objects for kernel data-only attacks with CopyKat |
|
|
|
π¦ Artifact π Appendix |
| Distributed Synthesis of Differentially Private Tabular Datasets |
|
|
|
π¦ Artifact π Appendix |
| Distributed Vector Commitments and Their Applications |
|
π¦ Artifact |
||
| Do Not Mention This to the User: Detecting and Understanding Malicious Agent Skills in the Wild |
|
|
|
π¦ Artifact π Appendix |
| Do They Get With the Program? Measuring Mitigation in a Solicited Vulnerability Notification Program |
|
|||
| Do You Need a Receipt? Anonymous Credential Revocation at Continental Scale via Private Record Certification |
|
|
|
π¦ Artifact π Appendix |
| Download More RAM: Dismantling Windows Operating System Defences with Mischievous Memory |
|
|
|
π¦ Artifact π Appendix |
| DualSentinel: A Lightweight Framework for Detecting Targeted Attacks in Black-box LLM via Dual Entropy Lull Pattern |
|
π¦ Artifact |
||
| DuetORAM: Two-Server Distributed ORAM with Constant Rounds and O(log N) Communication |
|
π¦ Artifact |
||
| E2E-AKMA: An End-to-End Secure and Privacy-Enhancing AKMA Protocol Against the Anchor Function Compromise |
|
π¦ Artifact |
||
| Efficient Threshold ML-DSA |
|
π¦ Artifact |
||
| Efficient and High-Accuracy Secure Two-Party Protocols for a Class of Functions with Real-number Inputs |
|
π¦ Artifact |
||
| Efficiently Provable Approximations for Non-Polynomial Functions |
|
|
|
π¦ Artifact π Appendix |
| End-to-End Encrypted Collaborative Documents |
|
π¦ Artifact |
||
| Enhanced Private Set Union from Secret-shared Private Membership Test |
|
|
|
π¦ Artifact π Appendix |
| Enjoy the Free Lunch, Someone Paid for Us: Escaping Resource Limits of MicroVM-based Containers |
|
π¦ Artifact |
||
| Estimating the amount of script-generated traffic in a mixture |
|
π¦ Artifact |
||
| Exploiting Hidden Resource Contention in Selective Speculation Defenses |
|
|
|
π¦ Artifact π Appendix |
| Exploiting PoH Time Semantics in Solana via Re-Anchoring and Forking |
|
π¦ Artifact |
||
| Exploring Privacy Negotiation Strategies for Camera-Equipped Smart Home Devices in Airbnb |
|
π¦ Artifact |
||
| Exposing Resource-Exhaustion DoS Vulnerabilities with Leak-Oriented Minimum Path Covers |
|
|
π¦ Artifact π Appendix |
|
| FABRICKED: Misconfiguring Infinity Fabric to Break AMD SEV-SNP |
|
π¦ Artifact |
||
| FABS: Fast Attribute-Based Signatures |
|
π¦ Artifact |
||
| FIRA: Enabling Automatic Forensic Investigation of Unmanned Aerial Vehicles |
|
|
|
π¦ Artifact π Appendix |
| FLOSS: Fast Linear Online Secret-Shared Shuffling |
|
|
|
π¦ Artifact π Appendix |
| FRAGJAM: DoS Attacks Using IP Reassembly Congestion |
|
π¦ Artifact |
||
| Fence2Pwn: KFENCE-Enabled Kernel Exploitation Bypassing Slab Hardening and Memory Tagging |
|
π¦ Artifact |
||
| Fend for Yourself! Backdoor Purification in Federated Graph Learning with an Evolving Knowledge Anchor |
|
|
|
π¦ Artifact π Appendix |
| FirmReBugger: A Benchmark Framework for Monolithic Firmware Fuzzers |
|
|
|
π¦ Artifact π Appendix |
| Firmenstein: Scaling Dynamic Analysis for Linux-Based Firmware Services via API-Centric Intervention Code Synthesis |
|
π¦ Artifact |
||
| Five Queries Are Enough: Query-Efficient and Surrogate-Free Membership Inference Attacks on RAG via Entailment |
|
|
|
π¦ Artifact π Appendix |
| FragFuse: Bypassing Access Control of Large Language Model Agents via Memory-Based Query Fragmentation and Fusion |
|
π¦ Artifact π Appendix |
||
| From Assistance to Autonomy: An Empirical Study of AI Use in a Live Capture-the-Flag (CTF) Competition |
|
|
|
π¦ Artifact π Appendix |
| From Easy to Hard++: Promoting Differentially Private Image Synthesis Through Spatial-Frequency Curriculum |
|
|
π¦ Artifact π Appendix |
|
| From Length to Content: Token-Length Side-Channel Attacks on Merged LLM API Outputs |
|
π¦ Artifact |
||
| From Mirai to Gorilla: Deep Dive into a Long-Lasting DDoS-for-Hire Botnet |
|
π¦ Artifact |
||
| From Symmetry toward Weak Asymmetry: Secure Steganography under the Receiverβs Partial Channel Knowledge |
|
π¦ Artifact |
||
| From Texts to Rules: Generating Sigma Rules with Large Language Models from Cyber Threat Reports |
|
π¦ Artifact |
||
| From Zero to Hero: Cross-modal-enhanced Adversarial Item Promotion Attack against Multimodal Recommender Systems |
|
π¦ Artifact |
||
| Fully Oblivious Differential Privacy for Frequency Estimation in the Augmented Shuffle Model with Trusted Processors |
|
π¦ Artifact |
||
| Fuzzing Open-Source GPU Hardware with SIMT Program Generation |
|
|
|
π¦ Artifact π Appendix |
| Garuda and Pari: Faster and Smaller SNARKs via Equifficient Polynomial Commitments |
|
π¦ Artifact |
||
| Generating Precise Format Specification for Network Protocols Through Adversarial LLM Interactions |
|
π¦ Artifact |
||
| GoodVibe: Security-by-Vibe for LLM-Based Code Generation |
|
π¦ Artifact |
||
| H3Act: Automated Measuring Semantic Conversion Anomalies of HTTP/3-to-HTTP/1.1 Translation in CDNs |
|
π¦ Artifact |
||
| HAMLOCK: HArdware-Model LOgically Combined attacK |
|
π¦ Artifact |
||
| HAMLOCK: HArdware-Model LOgically Combined attacK |
|
|
|
π¦ Artifact π Appendix |
| HasteBoots: Proving TFHE Programmable Bootstrapping in Seconds |
|
π¦ Artifact |
||
| Health Hazard, Handle with Care: Investigating the Privacy Risks of Androids Health Connect |
|
π¦ Artifact |
||
| Heli: Heavy-Light Private Aggregation |
|
|
|
π¦ Artifact π Appendix |
| High-Accuracy, Poisoning-Resilient Frequency Estimation in the Shuffle Model |
|
|
|
π¦ Artifact π Appendix |
| HijackKV: New Threat in Position-Independent KV Cache Reuse |
|
|
|
π¦ Artifact π Appendix |
| Hop: A Modern Transport and Remote Access Protocol |
|
|
|
π¦ Artifact π Appendix |
| Hydrangea: Optimistic Two-Round Partial Synchrony with Improved Fault Resilience |
|
π¦ Artifact |
||
| HyperAudit: Towards User Transparent and Highly Efficient System Auditing for Cloud Platforms |
|
π¦ Artifact |
||
| Icefish: Practical zk-SNARKs for Verifiable Genomics |
|
π¦ Artifact |
||
| Identifying Provenance of Generative Text-to-Image Models |
|
π¦ Artifact |
||
| Imitative Membership Inference Attack |
|
π¦ Artifact |
||
| InSPECtor: Improving SLEIGH Specification Veracity via Proxy |
|
π¦ Artifact |
||
| Inconsistent, Incomplete, and Insecure: A Survey of Account Security Interfaces |
|
π¦ Artifact |
||
| Inference Attacks Against Graph Generative Diffusion Models |
|
π¦ Artifact |
||
| Information Security in Small-Scale Protests: Surveillance of Ugandan Anti-EACOP Protesters |
|
π¦ Artifact |
||
| Injected and Leaked: Actively Inducing Side-channel Leakage Using Electromagnetic Injection And Hardware Non-Linearity |
|
|
π¦ Artifact π Appendix |
|
| InstantOMR: Oblivious Message Retrieval with Low Latency and Optimal Parallelizability |
|
|
|
π¦ Artifact π Appendix |
| InstrSem: Automatically and Generically Inferring Semantics of (Undocumented) CPU Instructions |
|
|
|
π¦ Artifact π Appendix |
| Interpolation-Based Optimization for Enforcing lp-Norm Metric Differential Privacy in Continuous and Fine-Grained Domains |
|
|
|
π¦ Artifact π Appendix |
| Invariant-Guided Logical Testing of Open RAN Controllers |
|
π¦ Artifact |
||
| IoT Product Page Data |
|
π¦ Artifact |
||
| Ira: Efficient Transaction Replay for Ethereum |
|
π¦ Artifact |
||
| JScamd: An Automated Static Taint Analysis Framework for Detecting Cryptographic API Misuses in JavaScript |
|
π¦ Artifact |
||
| JailbreakScope: Interpreting Jailbreak Mechanism through Representation and Circuit Analyses |
|
π¦ Artifact |
||
| Jailbreaking the AMD Secure Processor: Enabling Live Analysis of SEV-SNPs Undocumented Security Boundaries |
|
π¦ Artifact |
||
| Just One Bit Vector: Complement-Free Ring Confidential Transactions with Transparent Setup |
|
π¦ Artifact |
||
| KernelRCA: Facilitating Root Cause Analysis of Memory Corruptions in Linux Kernel with Contextual Causality Chain |
|
|
|
π¦ Artifact π Appendix |
| Khost: KVM-based Near Native MCU Firmware Rehosting |
|
|
π¦ Artifact π Appendix |
|
| Kintsugi: Empowering LLMs to Mitigate Web Vulnerabilities via Runtime Policy Injection |
|
π¦ Artifact |
||
| LPG: Raise Your Location Privacy Game in Direct-to-Cell LEO Satellite Networks |
|
|
π¦ Artifacts: 1, 2 π Appendix |
|
| Large-scale online deanonymization with LLMs |
|
|||
| Lethe: Purifying Backdoored Large Language Models with Knowledge Dilution |
|
π¦ Artifact |
||
| Leveraging Cryptographic Simulator Synthesis for Formally Verifying the FOO E-Voting Protocol -- Artifacts |
|
|
|
π¦ Artifact π Appendix |
| Libra: Pattern-Scheduling Co-Optimization for Cross-Scheme FHE Code Generation over GPGPU |
|
|
|
π¦ Artifact π Appendix |
| Liquidity Mining as an Attack Surface: Incentive-Induced Liquidity Attacks in Concentrated Liquidity Market Makers |
|
π¦ Artifact |
||
| Logos: Robust Sharding Blockchain With Fast Processing and Optimal Cross-Shard Overhead |
|
π¦ Artifact |
||
| LoongLeak: Architectural Cross-Privilege-Boundary Data Leakage on LoongArch CPUs |
|
|
|
π¦ Artifact π Appendix |
| Lost in Blockchain Address Misuse: Hidden Cross-Platform Risks and Their Security Impact |
|
π¦ Artifact |
||
| Lost in Encapsulation: Exploiting Open Tunnelling Hosts and Attacking Private Networks |
|
π¦ Artifact |
||
| Love, Lies, and Language Models: Investigating AIβs Role in Romance-Baiting Scams |
|
|
|
π¦ Artifact π Appendix |
| Low-Cost Hard-Label Adversarial Attack with Theoretical Foundations |
|
|
|
π¦ Artifact π Appendix |
| M-Step: A Single-Stepping Framework for Side-Channel Analysis on TrustZone-M |
|
|
|
π¦ Artifact π Appendix |
| MASLeak: Investigating and Exposing Intellectual Property Leakage Vulnerabilities in Multi-Agent Systems |
|
|||
| MATE: Policy-Aware Security Auditing for Mobile Agents via Synthesis-Driven Trajectory Learning |
|
|
|
π¦ Artifact π Appendix |
| MEPS: Privacy-preserving Edge-cloud Video Foundation Model Inference with Privacy Protectability |
|
π¦ Artifact |
||
| MHOT: Height-Optimized Authenticated Data Structure for Blockchain State Commitment |
|
π¦ Artifact |
||
| MOTION IN THE CLEAR: Reconstructing VR User Behavior from Network Traffic |
|
π¦ Artifact |
||
| MULCOTAINT: Towards Efficient Multi-tag Dynamic Taint Analysis via Hardware/Software Co-design |
|
π¦ Artifact |
||
| MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection Attacks |
|
π¦ Artifact |
||
| MarkNull: Model-Agnostic Watermark Removal in AI-Generated Images via On-Manifold Latent Manipulation |
|
π¦ Artifact |
||
| Maybe thereβs only one passkey?: Challenges Investigating and Remediating Adversarial Passkeys |
|
π¦ Artifact |
||
| Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening |
|
π¦ Artifact |
||
| Meerkat: Pushing the Practical Limits of Dynamic Bisection with PoC Mutation |
|
|
|
π¦ Artifact π Appendix |
| Melting the Flesh of PHPs Memory Hardening |
|
|
|
π¦ Artifact π Appendix |
| Membership Inference Attacks on Tokenizers of Large Language Models |
|
|
|
π¦ Artifact π Appendix |
| Memclave: Secure In-Memory Enclave for Untrusted Hosts |
|
|
|
π¦ Artifact π Appendix |
| Message Injection Attacks Against Signal |
|
|
|
π¦ Artifact π Appendix |
| NOIR: Privacy-Preserving Generation of Code with Open-Source LLMs |
|
π¦ Artifact |
||
| Network-Level Prompt and Trait Leakage in Local Research Agents |
|
π¦ Artifact |
||
| Non-Interactive Key Exchange from Lattices in the Standard Model |
|
π¦ Artifact |
||
| Not All Those Who Share Are Lost: Analyzing 25 Years of Cybersecurity Artifact Sharing Practices Through Automated Discovery |
|
|
|
π¦ Artifact π Appendix |
| Nudge: A Private Recommendations Engine |
|
π¦ Artifact |
||
| ORPHEUS: A Separation-Robust Proactive Defense for Singing Voice Conversion |
|
π¦ Artifact |
||
| OS-Sanitizer: System-wide Latent Defect Inference in Linux Applications |
|
|
|
π¦ Artifact π Appendix |
| Oblivious Signaling |
|
π¦ Artifact |
||
| On Evaluating the Robustness of Large Vision-Language Models via Untargeted Modality Alignment Breaking Adversarial Attack |
|
π¦ Artifact |
||
| On Improving Robustness of Deepfake Image Detectors |
|
|
π¦ Artifact π Appendix |
|
| One Bad Token Spoils the Barrel: Assessment, Detection, and Remediation of Glitch Tokens in Large Language Models |
|
π¦ Artifact |
||
| Opossum Attack: Application Layer Desynchronization using Opportunistic TLS |
|
π¦ Artifact |
||
| Orbit: Optimizing Rescale and Bootstrap Placement with Integer Linear Programming Techniques for Secure Inference |
|
|
|
π¦ Artifact π Appendix |
| Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems |
|
π¦ Artifact |
||
| PANGOLIN: Fuzzing Multilingual IoT Firmware with LLM-Driven Code Analysis |
|
π¦ Artifact |
||
| PHANTOM: Undermining Mobile System Availability via Malformed Installation Metadata |
|
π¦ Artifact |
||
| PICASSO: Scaling CHERI Use-After-Free Protection to Millions of Allocations using Colored Capabilities |
|
|
|
π¦ Artifact π Appendix |
| PICS: Private Intersection over Committed (and reusable) Sets |
|
|
|
π¦ Artifact π Appendix |
| PROBE+DETECT+MITIGATE (PDM): Enabling Cloud Tenants to Self-Defend against Microarchitectural Attacks |
|
π¦ Artifact |
||
| PVMark: Enabling Public Verifiability for LLM Watermarking Schemes |
|
π¦ Artifact |
||
| Patch-Guided Vulnerability Detection: Extracting Java API Security Rules via AttackβDefense Cross-Analysis |
|
π¦ Artifact |
||
| PatchWeaver: Risk-Bounded Autonomous Vulnerability Remediation Under Change-Management Policies |
|
|
|
π¦ Artifact π Appendix |
| Patcher: Post-Hoc Patching of Backdoored Large Language Models |
|
π¦ Artifact |
||
| Perils of Parallelism: Transaction Fee Mechanisms under Execution Uncertainty |
|
π¦ Artifact |
||
| Plain Text, Plain Risks: Measuring and Understanding HTTP Inclusion in Android WebViews at Scale |
|
|
|
π¦ Artifact π Appendix |
| Plaintext Recovery Against Post-Filtering Access Control |
|
|
|
π¦ Artifact π Appendix |
| Prezta: Provable Remote Execution of Zero-Trust Authorization using SNARKs |
|
|
|
π¦ Artifact π Appendix |
| Principled Design of Indexing Functions for Memory Coloring |
|
|
|
π¦ Artifact π Appendix |
| PrivacyShield: Relaying BLE Beacons to Counter Unsolicited Tracking |
|
|
|
π¦ Artifact π Appendix |
| Provable Secure Steganography Based on Adaptive Dynamic Sampling |
|
π¦ Artifact |
||
| Quantifying Large Language Model Attacks Through the Lens of Model Cognition |
|
|
π¦ Artifact π Appendix |
|
| Quorus: Efficient, Scalable Threshold ML-DSA Signatures from MPC |
|
|
|
π¦ Artifact π Appendix |
| RBOOT: Accelerating Homomorphic Neural Network Inference by Fusing ReLU within Bootstrapping |
|
π¦ Artifact |
||
| Raising the Flag: Detecting Missing Permission Controls in Mini-Program APIs |
|
π¦ Artifact |
||
| Rarus: A Succinct and Efficient Range Proof for Polynomial-based Vector Commitment |
|
|
|
π¦ Artifact π Appendix |
| RecStruct: Recovering Nested Struct Types from Stripped Binaries via Stack-Driven Unification |
|
|
π¦ Artifact π Appendix |
|
| Reference Implementation for Facade: High-Precision Insider Threat Detection Using Deep Contextual Anomaly Detection |
|
π¦ Artifact |
||
| Regular Expression Denial of Service Induced by Backreferences |
|
π¦ Artifact |
||
| Relay and Betray: Exploiting Client-Side Authority in Multi-User Mixed Reality |
|
|
|
π¦ Artifact π Appendix |
| Remise: Authorized Anonymous Communication Systems |
|
|
|
π¦ Artifact π Appendix |
| Residual-PAC Privacy: Automatic Privacy Control Beyond the Gaussian Barrier |
|
π¦ Artifact |
||
| Resilience amid Diffused Surveillance During a Political Movement in Bangladesh |
|
π¦ Artifact |
||
| Retrofit: Continual Learning with Controlled Forgetting for Binary Security Detection and Analysis |
|
|
|
π¦ Artifact π Appendix |
| Revealing the Dark Side of Smart Accounts: An Empirical Study of EIP-7702 Incurred Risks in Blockchain Ecosystem |
|
π¦ Artifact |
||
| Revelio: A Global Study of VoIP Blocking |
|
|
|
π¦ Artifact π Appendix |
| Robust Watermarks Meet Backdoored Models: Evading Diffusion Semantic Watermarks via Stealthy Backdoor |
|
π¦ Artifact |
||
| SING: Improving the Efficiency of MPC Protocol Assignment using Graph Neural Networks |
|
π¦ Artifact |
||
| SMASH: Scalable Maliciously Secure Hybrid Multi-party Computation Framework for Privacy-Preserving Large Language Models |
|
π¦ Artifact |
||
| SONIC: Concurrent Oblivious RAM & Data Structures for Low-Latency and High-Throughput |
|
|
|
π¦ Artifact π Appendix |
| SPIRIT: Batch Hintless Single-Server PIR via Stateful Ciphertext Conversion |
|
π¦ Artifact |
||
| SafeAdapt: Safety Alignment with Adaptive Thinking Allocation for Large Reasoning Models |
|
π¦ Artifact |
||
| SafeFFI: Efficient Sanitization at the Boundary Between Safe and Unsafe Code in Rust and Mixed-Language Applications |
|
|
π¦ Artifact π Appendix |
|
| Scribe: Low-memory SNARKs via Read-Write Streaming |
|
π¦ Artifact |
||
| Secpoline: A Scalable Approach to Build Secure In-Process Syscall Interposers |
|
|
π¦ Artifact π Appendix |
|
| Secure Distributed RSA Modulus Generation Revisited: A Faster and More Communication-Efficient Construction |
|
π¦ Artifact |
||
| Secure Protocol Composition under Dynamic Corruption: Models and Proofs |
|
|
|
π¦ Artifact π Appendix |
| Securing Retrieval-Augmented Code Generation via Contextual Knowledge Injection: A Case for Embedded IoT Applications |
|
π¦ Artifact |
||
| Security and Privacy Analysis of Tileβs Location Tracking Protocol |
|
π¦ Artifact |
||
| Security and Privacy Considerations for Confirming Payments in Rwandan Mobile Money Systems |
|
π¦ Artifact |
||
| Security in the Air: Understanding IoT Vendor Practices and the Economics of Over-the-Air Updates |
|
π¦ Artifact |
||
| Selling the Dream: Threat Modeling Intimate Insiders in Micro-businesses |
|
π¦ Artifact |
||
| Semantics Over Syntax: Uncovering Pre-Authentication 5G Baseband Vulnerabilities |
|
|
|
π¦ Artifact π Appendix |
| Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats |
|
|
π¦ Artifact π Appendix |
|
| Sequential Auditing for f-Differential Privacy |
|
π¦ Artifact |
||
| Shadowfax: Hybrid Security and Deniability for AKEMs |
|
|
|
π¦ Artifact π Appendix |
| Shielding QR Codes: Unveiling the Real-World Illicit Promotion Behind Adversarial QR Code |
|
π¦ Artifact |
||
| Shred-to-Shine Metamorphosis of (Distributed) Polynomial Commitments |
|
|
|
π¦ Artifact π Appendix |
| Side-Channel Attacks on Open vSwitch |
|
|
|
π¦ Artifact π Appendix |
| Silicon Heist: (Ransom) Attacks for Cloud FPGAs via Privilege Escalation |
|
π¦ Artifact |
||
| Single-Server Secure Aggregation with O(1) Server-Committee Communication at Scale |
|
π¦ Artifact |
||
| Sirens Whisper: Inaudible Near-Ultrasonic Jailbreaks of Speech-Driven LLMs |
|
π¦ Artifact |
||
| Sliced RΓ©nyi Pufferfish Privacy: Tractable Privatization Mechanism and Private Learning with Gradient Clipping |
|
π¦ Artifact |
||
| Sliding into the Flight Deckβs DMs: Practical Message Attacks on CPDLC |
|
π¦ Artifact |
||
| SoK: Another Arms Race -- 20 Years of (Anti-)Cheating in Video Games |
|
π¦ Artifact |
||
| SoK: Beyond Burnout -- A Gap Analysis of Psychological Harm in Cybersecurity Work |
|
π¦ Artifact |
||
| SoK: Capability Operating Systems: Is the Future Finally Here? |
|
π¦ Artifact |
||
| SoK: Colluding Adversaries in Machine Learning Pipelines |
|
π¦ Artifact |
||
| SoK: DARPAs AI Cyber Challenge (AIxCC): Competition Design, Architectures, and Lessons Learned |
|
π¦ Artifact |
||
| SoK: Deep Learning-based Physical Side-channel Analysis |
|
π¦ Artifact |
||
| SoK: History Doesnt Repeat Itself, but Android Design-Level Vulnerabilities Rhyme in OpenHarmony |
|
π¦ Artifact |
||
| SoK: On the Fragility of Memory Error Exploit Mitigations |
|
|
|
π¦ Artifact π Appendix |
| SoK: PHILTER: Uncovering Security and Functional Gaps in AI-based Phishing Website Detection Literature via an LLM-based Reasoning Framework |
|
π¦ Artifact |
||
| SoK: Security of Cyber-physical Systems Under Intentional Electromagnetic Interference Attacks |
|
π¦ Artifact |
||
| SoK: The Pitfalls of Deep Reinforcement Learning for Cybersecurity |
|
|
|
π¦ Artifact π Appendix |
| Sok: Private Transformer-based Model Inference |
|
π¦ Artifact |
||
| SophOMR: Improved Oblivious Message Retrieval from SIMD-Aware Homomorphic Compression |
|
|
|
π¦ Artifact π Appendix |
| Source Code: Assumption-Free Fuzzy PSI via Predicate Encryption |
|
π¦ Artifact |
||
| Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order Processors |
|
|
|
π¦ Artifact π Appendix |
| StackWarp: Breaking AMD SEV-SNP Integrity via Deterministic Stack-Pointer Manipulation through the CPUs Stack Engine |
|
|
|
π¦ Artifact π Appendix |
| Static Detection of TOCTOU Bugs Caused by Kernel Races |
|
π¦ Artifact |
||
| Sticking their heads out above the parapets: Lived Experiences of Legal Risks in Research |
|
π¦ Artifact |
||
| Streaming Function Secret Sharing and Its Applications |
|
π¦ Artifact |
||
| Sy-FAR: Symmetry-based Fair Adversarial Robustness |
|
π¦ Artifact |
||
| Systematically Detecting Privacy Violations in Video Conferencing via Cross-Modal Consistency |
|
π¦ Artifact |
||
| TAT: Attesting Trajectory Integrity of Industrial Robotic Arms |
|
π¦ Artifact |
||
| TED: Abusing Tunnel Hosts and IPv6 Extension Headers for Pulsing DoS Attacks |
|
π¦ Artifact |
||
| TIMESLICE-SANDWICH: A GPU Side-Channel Attack Exploiting Time-Sliced Scheduling |
|
π¦ Artifact |
||
| Take the RedPill: Boosting MCU Firmware Fuzzing with Faithful Hardware Emulation |
|
π¦ Artifact |
||
| Tap Without Tapping: A Tag Discovery Forgery Attack on Android NFC |
|
|
|
π¦ Artifact π Appendix |
| Technical Analysis of the Geedge Networks Firewall Source Code Leak |
|
π¦ Artifact |
||
| TensorZKP: Repurposing GPU Tensor Cores for High-Performance Zero-Knowledge Proofs |
|
π¦ Artifact |
||
| The Adverse Effects of Omitting Records in Differential Privacy: How Sampling and Suppression Degrade the PrivacyβUtility Tradeoff (USENIX Security 2026 Artifact) |
|
|
|
π¦ Artifact π Appendix |
| The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy Again |
|
π¦ Artifact |
||
| The Impact of S&P Controls on U.S. Users Emotional Engagement with Generative AI Chatbots (Artifact) |
|
π¦ Artifact |
||
| The Ivory Tower Syndrome: Operators Reflections on Academic BGP Security Solutions |
|
|||
| The Perils of Flexibility: Uncovering Application-Layer Vulnerabilities in Cosmos SDK Customization Points |
|
π¦ Artifact |
||
| The Prompt Stealing Fallacy: Rethinking Metrics, Attacks, and Defenses |
|
π¦ Artifact |
||
| The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web |
|
|
|
π¦ Artifact π Appendix |
| TopFeaRe: Locating Critical State of Adversarial Resilience for Graphs Regarding Topology-Feature Entanglement |
|
π¦ Artifact |
||
| Toward Understanding the Security Implications in Python Configuration Files |
|
π¦ Artifact |
||
| Towards Generality: Task-Adaptive Binary Analysis via Semantic Retrieval and Verifiable Reasoning |
|
π¦ Artifact |
||
| Towards Practical Few-shot Multi-tab Website Fingerpinting |
|
π¦ Artifact |
||
| Tracegram: Framing Trace-Level Traffic Analysis with Temporally-Aware Multiple Instance Learning |
|
π¦ Artifact |
||
| Transparent Dictionaries from Polynomial Commitments |
|
π¦ Artifact |
||
| TrioFuzz: A Three-Tier Architecture for Adaptive Strategy Selection in Fuzzing |
|
π¦ Artifact |
||
| TrojPix: Electromagnetic Covert Channels via Imperceptible Pixel Modulation |
|
π¦ Artifact |
||
| Trust Nothing: RTOS Security without Run-Time Software TCB |
|
|
|
π¦ Artifact π Appendix |
| Trusting What You Cannot See: Auditable Fine-Tuning and Inference for Proprietary AI |
|
π¦ Artifact |
||
| Trustworthy and Confidential SBOM Exchange |
|
|
|
π¦ Artifacts: 1, 2 π Appendix |
| Turn Your Face Into An Attack Surface: Screen Attack Using Facial Reflections in Video Conferencing |
|
π¦ Artifact |
||
| Unbalanced Fuzzy Private Set Intersection for $L_{\infty}$ Distance: Achieving Sublinear Communication with Large Set Size |
|
π¦ Artifact |
||
| UncoreBleed: AEX-Free, High-Resolution, and Low-Noise Side-Channel Attacks on SGX Enclaved Execution |
|
|
π¦ Artifact π Appendix |
|
| Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis |
|
π¦ Artifact |
||
| United We Defend: Collaborative Membership Inference Defenses in Federated Learning |
|
|
π¦ Artifact π Appendix |
|
| Unlocking the True Potential of Decryption Failure Oracles: A Hybrid Adaptive-LDPC Attack on ML-KEM Using Imperfect Oracles |
|
π¦ Artifact |
||
| Unveiling the Pitfalls of Data-Free Backdoor Detection Against Pre-Trained Models |
|
π¦ Artifact |
||
| VOID: Defeating Unauthorized Mimicry in Latent Diffusion Models |
|
|
|
π¦ Artifact π Appendix |
| VROOM: Accelerating (Almost All) Number-Theoretic Cryptography Using Vectorization and the Residue Number System |
|
|
|
π¦ Artifact π Appendix |
| VSG-Safe: Spotting NSFW Video through Cross-Frame Evidence |
|
π¦ Artifact |
||
| VeCT: Secure and Efficient Constant-Time Code Rewriting with Vector Extensions |
|
|
|
π¦ Artifact π Appendix |
| ViPer Strike: Defeating Visual Reasoning CAPTCHAs via Structured VisionβLanguage Inference |
|
π¦ Artifact |
||
| VidLeaks: Membership Inference Attacks Against Text-to-Video Models |
|
π¦ Artifact |
||
| VΞ΅rity: Verifiable Local Differential Privacy |
|
π¦ Artifact |
||
| WAVED: Principled Identification of Off-Path Exploitable Weak Verifications within the TCP/IP Protocol Suite |
|
|
|
π¦ Artifact π Appendix |
| WILD Attack: Stealthy Undermining of Wi-Fi-Based Geolocation Through Remote Crowdsourced Data Injection |
|
π¦ Artifact |
||
| WarrInt: Integrity Validation for Criminal Legal Process |
|
π¦ Artifact |
||
| What Adults Will (and Wont) Do to Prove Their Age: Empirical Evidence from a Deceptive Web Experiment |
|
|
|
π¦ Artifact π Appendix |
| What Users Ask, Policies Miss: Unveiling the Gap Between Community-Expressed Privacy Concerns and LLM Provider Policies |
|
π¦ Artifact |
||
| What You Decode Depends on Where You Stand: Distance-Based Optical QR Code |
|
π¦ Artifact |
||
| What the Eyes See, the LLMs Miss: Exploiting Human Perception for Adversarial Text Attacks |
|
|
|
π¦ Artifact π Appendix |
| When Address Learning Goes Wrong: Inducing Forwarding Loops and DoS Amplification in SDN |
|
|
|
π¦ Artifact π Appendix |
| When Authorization Loses Its Meaning: Breaking and Fixing Third-Party Online Payments |
|
π¦ Artifact |
||
| When Fun Turns Toxic: A First Look at Aggressive Advertising in Mini-games |
|
π¦ Artifact |
||
| When HTTP 402 Meets the Blockchain: Risks on Emerging x402 Payments |
|
|
|
π¦ Artifacts: 1, 2 π Appendix |
| When Updates Backfire: A Black-Box Security Analysis of Desktop Software Update Mechanisms |
|
π¦ Artifact |
||
| When the Aggregator Cheats: Data-Free Backdoors in Federated LLM-based QA Systems |
|
π¦ Artifact |
||
| Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore |
|
π¦ Artifact |
||
| Window-based Membership Inference Attacks Against Fine-tuned Large Language Models |
|
π¦ Artifact |
||
| Wormholes in the File System: Understanding the Misunderstanding of Symlinks |
|
|
|
π¦ Artifact π Appendix |
| XCFI: Comprehensive Control-Flow Integrity for Arm TrustZone-M |
|
|
|
π¦ Artifact π Appendix |
| XGuardian: Towards Explainable and Generalized AI Anti-Cheat on FPS Games |
|
|
|
π¦ Artifact |
| You Know Why, but Still Rely: The Impact of Explainable AI on Trust, Task Load, and Performance in Cybersecurity Decision-Making |
|
π¦ Artifacts: 1, 2, 3, 4 |
||
| Your Keywords Know Each Other: Breaking SSE with <1% Leaked Documents |
|
|
|
π¦ Artifact π Appendix |
| Your imaging may be stone-cold normal, but if they look sick, theyβre going to get admitted: An Investigation of Cliniciansβ Perceptions of Impact & Likelihood of Security Failures |
|
π¦ Artifact |
||
| Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers |
|
π¦ Artifact |
||
| ZipPIR: High-throughput Single-server PIR without Client-side Storage |
|
|
|
π¦ Artifact π Appendix |
| Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments |
|
π¦ Artifact |
||
| iROV: Breaking the Silence of RPKI with Interactive Validation |
|
π¦ Artifact |
||
| kSFS: Repurposing a Microkernel-like Interface for Fast and Secure In-Kernel Linux File Systems |
|
|
|
π¦ Artifact π Appendix |
| microSCALE: Static Analysis for Microarchitectural Side-channel Leakage Evaluation |
|
|
π¦ Artifact π Appendix |
|
| mmCipher: Batching Post-Quantum Public Key Encryption Made Bandwidth-Optimal |
|
|
|
π¦ Artifact π Appendix |
| sigma-rs: A Modular Approach for Keyed-Verification Anonymous Credentials |
|
|
|
π¦ Artifact π Appendix |
| vCause: Efficient and Verifiable Causality Analysis for Cloud-based Endpoint Auditing |
|
π¦ Artifact |